How Propel protects your data

Propel produces identification badges and manages device inventory for organisations. To do that we hold the data a badge needs — a person's name, photograph, employer and a delivery address — for as short a time as the work allows, in a platform we built and can show you the inside of. This page is generated from our own controls register: every status below is data with a verification date, not marketing copy, and a control we have not finished says so.

Compliance posture, plainly

Propel does not yet hold a SOC 2 report. Our controls are mapped to the SOC 2 Trust Services Criteria and the HIPAA Security Rule safeguards, and the evidence behind each one is available to customers and approved reviewers. A third-party audit is on the roadmap; we would rather show you the register than a badge.

Controls implemented
21 / 33
5 partial · 7 planned
Published policies
2
names and summaries public; full text on request
Subprocessors
10
30-day notice before a change
Register last verified
—
most recent control verification
Multi-factor authentication on every administrative account

Staff sign in with a passkey or an authenticator app. The platform checks that every active employee has one enrolled.

Least-privilege access, by role and by application

Staff hold explicit roles; each application connects to the database with a role granted only what it needs; the public API cannot read what it does not serve.

Encryption in transit and at rest

TLS everywhere, provider-managed encryption at rest, credentials hashed, API keys stored as hashes and shown once, webhook secrets rotated with an overlap.

A retention schedule with a mechanism behind it

Badge files are deleted 30 days after shipping, shipping documents at 90, everything within a year — by a nightly job that writes an audit row, not by a promise.

Audited access to cardholder records

Every change to a badge order — status, hold, print, ship, cancellation — is recorded with the actor and the time.

Incident response with a 72-hour clock

A documented process: contain within 30 minutes, preserve evidence, notify affected clients within 72 hours of becoming aware of a breach.

No machine-learning training on client content

A binding commitment in our Terms and Privacy Policy, and an internal AI-usage policy that says which tools may be used and what may never go into a prompt.

Invite-only client portals

Access to the Developers Portal, Propel Stock and this Trust Center's gated documents is granted by Propel staff to a named person, revocable at once, and may expire.

Need the full documents?

Customers: sign in with your Propel account (your account manager grants Trust Center access). Prospects and reviewers: request access and we will send a time-limited link. Questions go to security@propelbsc.com.